Earlier quoted context omitted.
My super cynical view is that the whole genre of "quantum safe" cryptography is being promoted to try and encourage adoption of weak encryption... Its felt like FUD based on FUD for a while. Not that I really trust traditional encryption that much either. There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... Hate making cynical comments tho, they al…
Quantum safe crypto isn’t FUD, NIST’s steadfast refusal to specify a dual system, especially given their historical laundering of NSA back doors is super questionable, but there exist (at least one that I know of) crypto systems that have no exploitable bias. The problem is the impractically large key sizes. Afaict a lot of pqc work is trying to reduce the key sizes to something reasonable.
“Quantum-Safe” Crypto Hacked by 10-Year-Old PC
51–60 of 187 posts
Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#52Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#53What is the possibility that cryptowallets can succumb to these kinds of attacks? How is it possible that Satoshi's wallet has still, after so many years, not been hacked using a brute force mechanism?
Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#54Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#55What is the possibility that cryptowallets can succumb to these kinds of attacks? How is it possible that Satoshi's wallet has still, after so many years, not been hacked using a brute force mechanism?
I'm sure many people are trying. On a slightly related note - I wonder what the market effect would be on bitcoin (and possibly crypto as a whole) if anyone managed to transfer money out of the wallet, would it crash the currency?
Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#56Earlier quoted context omitted.
He's wrong about the "cryptographic agility" stuff, at least the way he's framed it. But then, another place where I'd part company with him is about the urgency for getting PQC slotted into real-world systems.
Why do you think he's wrong? He's essentially saying IT systems need to be designed with the expectation that cryptographic algorithms will be attacked and may need to be replaced, as I understand it.
What he says instead is that "it’s vital that our systems be able to easily swap in new algorithms when required". That approach has a virtually unbroken track record of failure. It demands negotiation, which introduces bugs, and even after you get past that, it doesn't work: you literally always end up with downgrade attacks (see, for instance, the DNSSEC work at Black Hat this year). Sometimes those downgrade attacks introduce vulnerabilities for parties that would never have even attempted to use the legacy crypto.
Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#57Earlier quoted context omitted.
He's wrong about the "cryptographic agility" stuff, at least the way he's framed it. But then, another place where I'd part company with him is about the urgency for getting PQC slotted into real-world systems.
Why do you think he's wrong? He's essentially saying IT systems need to be designed with the expectation that cryptographic algorithms will be attacked and may need to be replaced, as I understand it.
Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#58Earlier quoted context omitted.
My super cynical view is that the whole genre of "quantum safe" cryptography is being promoted to try and encourage adoption of weak encryption... Its felt like FUD based on FUD for a while. Not that I really trust traditional encryption that much either. There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... Hate making cynical comments tho, they al…
Quantum safe crypto isn’t FUD, NIST’s steadfast refusal to specify a dual system, especially given their historical laundering of NSA back doors is super questionable, but there exist (at least one that I know of) crypto systems that have no exploitable bias. The problem is the impractically large key sizes. Afaict a lot of pqc work is trying to reduce the key sizes to something reasonable.
Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#59You KNOW they first had to do this in the normal way (large scale, distributed servers)..... and cracked it in like a second. Then for grins, the engineer HAD to say "I wonder if I could do this on my old Mac mini". And it worked. And for embarrassment of the original design, the story, and clickbait... they did it on that old machine
Source: worked with algebra researchers using Magma.
Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC
#60Yet I still think there's a good "look beyond your strengths" lesson here.